Impact
This vulnerability is an unauthenticated denial‑of‑service attack that targets the API endpoint of Hewlett Packard Enterprise AOS‑CX. An attacker can send crafted requests without requiring credentials, causing the service to stop functioning or become unresponsive. The impact is loss of availability for users or dependent processes, potentially disrupting network management operations.
Affected Systems
The affected product is Hewlett Packard Enterprise AOS‑CX. No specific version information was provided; therefore, any deployment of AOS‑CX is potentially vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS score is unavailable, so the exploit probability cannot be quantified but the lack of authentication makes the attack easier. The vulnerability is not listed in CISA KEV catalog, but it could still be actively targeted. An attacker could repeatedly hit the API endpoint, exhausting resources or triggering a crash, leading to service interruption. Mitigation requires applying the vendor's patch or implementing additional controls such as rate limiting or API gateway restrictions.
OpenCVE Enrichment